Marco Squarcina
banner
minimalblue.bsky.social
Marco Squarcina
@minimalblue.bsky.social
Senior Scientist @TU Wien / Web & Mobile Security / #drumandbass DJ
🚩 with @mhackeroni.bsky.social We_0wn_Y0u kukhofhackerei Team Austria
🔗 https://minimalblue.com/
Reposted by Marco Squarcina
🌟 Want to help shape #MADWeb 2026? Nominate yourself for the Program Committee! Deadline: Oct 31, 2025 ⏰ Consider applying even if you don't have extensive reviewing experience!

forms.gle/UovLWS78aa3t...
MADWeb 2026 PC Nomination Form
The web connects billions of devices, running a plethora of clients, and serves billions of users every day. To cope with such a widespread adoption, the web constantly changes. This is evident by som...
forms.gle
October 7, 2025 at 7:30 PM
🇦🇹 Team Austria placed 8th at #HITCON #CTF as part of the qualifier for #ECSC2025 in Warsaw. Everyone did a fantastic job, so proud of the team. We'll select the 10 final members in the next days, stay tuned!

@hitcon.org @tuwien.at @informatics.tuwien.ac.at @cysecwien.bsky.social @hofhackerei.at
August 25, 2025 at 7:34 AM
Meanwhile, our plane here in Vegas is "too heavy" and we can't take off. They are asking people to leave to reduce the weight. Please tell me this is perfectly normal.
After a great run at #defcon33 #CTF, I'm heading to Seattle to attend #USENIX Sec. DM me if you'd like to meet up and join us Thursday at midday for our talk on #TapTrap (track 4) with @beerphilipp.bsky.social !

taptrap.click

@lindorfer.in @cysecwien.bsky.social @informatics.tuwien.ac.at
TapTrap: Animation‑Driven Tapjacking on Android
taptrap.click
August 13, 2025 at 1:04 AM
After a great run at #defcon33 #CTF, I'm heading to Seattle to attend #USENIX Sec. DM me if you'd like to meet up and join us Thursday at midday for our talk on #TapTrap (track 4) with @beerphilipp.bsky.social !

taptrap.click

@lindorfer.in @cysecwien.bsky.social @informatics.tuwien.ac.at
TapTrap: Animation‑Driven Tapjacking on Android
taptrap.click
August 13, 2025 at 1:01 AM
From starting @mhackeroni.bsky.social in 2018 to heading @hofhackerei.at to 9th place at @defcon.bsky.social #CTF finals this year: what a journey.

This team is amazing, I couldn't be prouder of all of them and the best is yet to come! 🔥

@cysecwien.bsky.social @tuwien.at @informatics.tuwien.ac.at
We got 9th place at @defcon.bsky.social #CTF! Props to all finalists for an intense fight over the past three days and congrats to MMM for taking the win.

Thanks to Nautilus Institute for the neat setup this year, we had a blast.

Until next time, Vegas!

#DEFCON #DEFCON33
August 12, 2025 at 2:07 AM
First wave of our team (me included) is on the way to @defcon.bsky.social #CTF. Huge thx to the companies and unis backing us, we're extremely grateful.

Special shoutout to @tuwien.at for the early support, as well as everyone who joined after.

We'll give our best, wish us luck!

See you Vegas 🌴🚩
Bringing 30 people to Las Vegas for DEFCON CTF is a massive challenge! Huge THANK YOU🙏 to our sponsors:

💎 Dynatrace, Erste Bank und Sparkasse
🥇 TU Wien, TU Graz, SBA Research
🥈 FH St. Pölten, JKU Linz, Bosch, Siemens
🛡️ Cyber Security Austria

You made this possible!
August 5, 2025 at 8:09 PM
I'm part of the team that discovered the #TapTrap vulnerability. We confirmed that @grapheneos.org has properly fixed it, as detailed on our site taptrap.click

Despite a small factual error, it's good to see #GrapheneOS getting some media attention.
July 22, 2025 at 6:53 PM
Reposted by Marco Squarcina
foxnews.com/tech/new-and...

> GrapheneOS, a security-focused operating system based on Android, confirmed that its current version is also affected. However, it plans to release a fix in its next update.

No, we said that on July 7 and then shipped grapheneos.org/releases#202... fixing it.
July 22, 2025 at 3:58 AM
ECSC 2025 prep has begun! First Team Austria qualifier wrapped up with 30 participants focusing on #ENOWARS and #DUCTF. Great vibes. Thanks to Ikarus Security for hosting us and everyone who joined! #ECSC2025 @tuwien.at @informatics.tuwien.ac.at @cysecwien.bsky.social
July 21, 2025 at 1:40 PM
Our #TapTrap attack got covered in @tuwien.at's news!

This was such a fun project. Congrats to @beerphilipp.bsky.social on his second first-author paper at a top-tier conference ❤️

We'll present the paper at #USENIX in Seattle on August 14 . Looking forward to catching up with some of you there!
July 17, 2025 at 11:59 AM
For the second year in a row, @tuwien.at students have nominated our Introduction to Security course among the finalists for the Best Teaching Award!

Balancing research, teaching & outreach isn't easy, but we give it our all.

🔗 www.tuwien.at/tu-wien/aktu...

CC @informatics.tuwien.ac.at
Das sind die Best Teaching Award-Finalist_innen 2025
Die Jury hat entschieden, für wen die Eulenjagd weitergeht.
www.tuwien.at
July 15, 2025 at 11:52 PM
Our new Android attack, #TapTrap, is getting media coverage — so here's a quick explainer.

It's a new tapjacking technique that exploits Android's UI animations to hijack user taps without requiring any permissions. @beerphilipp.bsky.social will present it at #USENIX Sec'25.

🌐 taptrap.click
TapTrap: Animation‑Driven Tapjacking on Android
taptrap.click
July 10, 2025 at 4:35 PM
It has been an honor to organize the bootcamp for 3 years in a row, and I am proud that it's getting better every time. Thanks to CSA, @cysecwien.bsky.social, ENISA, Joe Pichlmayer, Manuel Reinsperger and the entire team for making this possible.

See you all next year ♥️ #CYBER #ECSC2025
tuwien.at TU Wien @tuwien.at · Jul 10
Die TU Wien war Gastgeberin der dritten Auflage des Wiener International Boot Camp for Ethical Hacking und begrüßte 150 Teilnehmer_innen aus zehn EU-Ländern und das Team Europe. Die dreitägige Veranstaltung bot intensive, praktische Schulungen und Networking. www.tuwien.at/tu-wien/aktu...
Drei Tage Ethical Hacking an der TU Wien
Das Wiener International Boot Camp for Ethical Hacking kehrt an die TU Wien zurück
www.tuwien.at
July 10, 2025 at 3:39 PM
Reposted by Marco Squarcina
Help us choose our mascot! 🐾

Nautilus Institute is asking us to send them a animal mascot for the DEFCON CTF, and we need your help to pick the cutest contender!
Dive into the threat to meet the 8 adorable candidates.

#KuKHofhackerei #defcon33 #ctf #Mascot
June 12, 2025 at 1:01 PM
My team @kukhofhackerei.bsky.social is heading to the DEF CON CTF finals this August in Las Vegas 🔥

We're now looking for sponsors to help cover the trip. If you're interested in supporting us, please get in touch or share this around.

Call for sponsors at hofhackerei.at 🇦🇹

Thank you!

#CTF #DC33
May 15, 2025 at 3:08 PM
After many years of battles with @mhackeroni.bsky.social, I'm blown away to announce that we've qualified for the #DEFCON CTF finals with KuK Hofhackerei 🇦🇹 this year!

New friends, same love. Couldn't be prouder of this team.

Thanks to nautilus.institute for organizing and see you in Vegas! 🚩
April 14, 2025 at 12:54 PM
The 2nd wave of challenges for the Austria Cyber Security Challenge #ACSC will be live in 1h! You have 1 month left to compete and prove your skills!

I contributed a hard web challenge this time, let's see who can solve it 👀

Ready? 👉 acsc.land

@informatics.tuwien.ac.at @cysecwien.bsky.social
Austria Cyber Security Challenge 2025
acsc.land
April 1, 2025 at 2:59 PM
Reposted by Marco Squarcina
And the best paper award sponsored by @paloaltonetworks.bsky.social goes to...

📜 Can Public IP Blocklists Explain Internet Radiation?

by D. Ravalico, S. Cossaro, R. Valentim, M. Trevisan, and I. Drago!

Congratulations 👏

#MADWeb #NDSSsymposium2025
March 2, 2025 at 6:05 PM
Reposted by Marco Squarcina
Can't wait for Friday? Get a sneak peek at #MADWeb '25 papers now! 📄✨ All papers are live on our website: madweb.work

Safe travels, and see you in San Diego! ✈️
#NDSSsymposium2025
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
madweb.work
February 26, 2025 at 11:19 PM
Reposted by Marco Squarcina
We're thrilled to announce Nick Nikiforakis (Stony Brook University) as our first keynote speaker of #MADWeb '25!

🎤 Building on Top of Shifting Sands: Web Security Through the Lens of Content Integrity

Don't miss it!

See the full program at madweb.work
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
madweb.work
February 12, 2025 at 12:55 PM
Reposted by Marco Squarcina
Our 2nd Keynote is here! 🚨

We're excited to have Frederik Braun @freddyb.bsky.social (Mozilla) at #MADWeb '25!

🎤 With Carrots & Sticks: Can the Browser Handle Web Security?

Join us in San Diego to attend this session!

Full program: madweb.work#program
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
madweb.work
February 12, 2025 at 1:04 PM
Reposted by Marco Squarcina
The #MADWeb '25 program is live!

We've got 9 full papers, 3 work-in-progress papers, and 2 exciting keynotes lined up. Huge thanks to all the authors and the program committee!

Check out the details and get ready for a great event! 🔥

🔗 madweb.work#program

See you in San Diego! #NDSS #websecurity
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
madweb.work
February 12, 2025 at 12:24 PM
Reposted by Marco Squarcina
Nominations are now open for the Top 10 Web Hacking Techniques of 2024! Browse the contestants and submit your own here:
portswigger.net/research/top...
Top ten web hacking techniques of 2024: nominations open
Nominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an
portswigger.net
January 8, 2025 at 2:09 PM
Reposted by Marco Squarcina
🚨 Deadline Extended 🚨

By popular demand, the #MADWeb submission deadline is now January 14, 2025 (AoE)! 🗓️

You still have 1 week to send your papers and join us in San Diego!

📜 Submit here: madweb25.hotcrp.com
🔗 Details: madweb.work

Spread the word!

#websec #cfp #ndss
MADWeb 2025
madweb25.hotcrp.com
January 8, 2025 at 3:43 PM
Please consider submitting your work and help us spread the word! #MADWeb
Just 4 days left to submit your papers to #MADWeb! 🚨 Remember, we welcome work-in-progress submissions, and you can opt out of proceedings if you're seeking feedback to refine and resubmit later!

📜 Submit here: madweb25.hotcrp.com
🔗 Website: madweb.work
MADWeb 2025
madweb25.hotcrp.com
January 6, 2025 at 3:56 PM